Companies House BLUNDER! đ±
Why It Matters
The flaw jeopardizes corporate data integrity and erodes trust in governmentârun digital services, prompting immediate remediation and broader reforms in publicâsector cybersecurity.
Key Takeaways
- âąCompanies House exposed critical authentication flaw in public portal.
- âąExperts label vulnerability as âschoolboy errorâ and âscandalous incompetence.â
- âąLack of twoâfactor verification lets attackers hijack company records.
- âąReviewers urge immediate site shutdown until proper fix implemented.
- âąIncident highlights systemic weaknesses in UK government digital infrastructure.
Summary
The video spotlights a serious security breach at Companies House, the UKâs official register of corporate entities. A flaw in the portalâs authentication logic allows a userâs account to be linked to any company without requiring a valid twoâfactor authentication token, effectively exposing sensitive corporate data.
Industry veterans â an IT specialist with 35 years of experience, a former software developer, and several security analysts â condemn the oversight as a âschoolboy errorâ and âscandalous incompetence.â They explain that the system merely checks whether a token was sent, not whether it was completed, and that the vulnerability should have been caught during testing. One expert recommends disabling the site until a robust fix is deployed.
The commentators quote each other sharply: Chris BS calls the situation âa horror show of stupidity,â Decadence calls it âwild vulnerability,â and Ian labels the governmentâs digital services âa complete shambles.â Another veteran likens the fiasco to the infamous COVIDâtracking app built on an OfficeâŻ97 spreadsheet, underscoring a pattern of neglect.
The breach threatens business confidence, potentially allowing malicious actors to alter or view company filings. It underscores the urgent need for the UK government to overhaul its digital procurement, testing, and security practices, and it raises questions about regulatory oversight of critical publicâsector IT systems.
Comments
Want to join the conversation?
Loading comments...